VYPR
Unrated severityNVD Advisory· Published Jan 3, 2011· Updated Jun 16, 2026

CVE-2010-3876

CVE-2010-3876

Description

net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <2.6.37
    • cpe:2.3:o:linux:linux_kernel:2.6.37:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:2.6.37:rc1:*:*:*:*:*:*
    • (no CPE)range: <2.6.37-rc2
  • OpenSUSE/openSUSE2 versions
    cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp1:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp3:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

23

News mentions

0

No linked articles in our index yet.